6.1

CVE-2016-8359

An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12. The web application fails to sanitize user input, which may allow an attacker to inject script or execute arbitrary code (CROSS-SITE SCRIPTING).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoxaIologik E1200 Series Firmware Version <= 2.4
   MoxaIologik E1210 Version-
   MoxaIologik E1212 Version-
   MoxaIologik E1214 Version-
   MoxaIologik E1241 Version-
   MoxaIologik E1242 Version-
   MoxaIologik E1260 Version-
   MoxaIologik E1262 Version-
MoxaIologik E1200 Series Firmware Version <= 2.3
   MoxaIologik E1211 Version-
   MoxaIologik E1240 Version-
MoxaIologik E1200 Series Firmware Version <= 2.5
   MoxaIologik E1213 Version-
MoxaIologik E2200 Series Firmware Version <= 3.11
   MoxaIologik E2214 Version-
   MoxaIologik E2240 Version-
   MoxaIologik E2242 Version-
   MoxaIologik E2262 Version-
MoxaIologik E2200 Series Firmware Version <= 3.12
   MoxaIologik E2210 Version-
   MoxaIologik E2260 Version-
MoxaIologik E2200 Series Firmware Version <= 3.13
   MoxaIologik E2212 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.641
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.